WhatsApp API Modification By Vangal
OpenSSF/OSV advisory MAL-2026-16103 confirms this npm version as malicious. package.json declares `libsignal` with the source `github:RILLYZY/libsignal-node`, an unpinned reference to a third-party GitHub repository with no tag or commit SHA. On `npm install`, npm clones that repository's default branch HEAD and runs any lifecycle scripts contained in it; libsignal-node ships a native addon with build-time scripts...
This report applies to @neroxkira/vangal-baileys@1.0.1.
1.0.0, 1.0.1
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.